CloudMap
漏洞情报库
漏洞库
厂商
产品
风险排行
开发者中心
开始检索
↗
VULNERABILITY INTELLIGENCE
漏洞情报库
组合风险、利用情报和受影响对象,快速定位需要优先处置的漏洞。
验证信息保护
仅展示 PoC 是否收录
不公开内容、路径和下载地址
⌕
/
搜索漏洞
10,858
条匹配记录
PoC
绿色表示已收录,灰色表示暂无
漏洞与影响对象
漏洞类型
风险等级
CVSS
EPSS
PoC 状态
披露时间
Content-Security-Policy Bypass - Baidu Map API
跨站脚本攻击
中危
—
—
PoC
2025/05/06
Content-Security-Policy Bypass - Mail.ru Connect
跨站脚本攻击
中危
—
—
PoC
2025/05/06
Content-Security-Policy Bypass - Swiftype API
跨站脚本攻击
中危
—
—
PoC
2025/05/06
Lantronix XPort 6.10.0.1 - Unauthenticated Access
Lantronix XPort
安全配置错误
高危
—
—
PoC
2025/05/06
CVE-2024-13322
Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injection
ads_pro
SQL注入
高危
7.5
1.8%
PoC
2025/05/02
CVE-2025-27007
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
suretriggers
不正确的权限分配
严重
9.8
53.9%
PoC
2025/05/01
CVE-2025-27134
RCE
Joplin 3.3.3 Server - Privilege Escalation
joplin
身份验证绕过
高危
8.8
2.2%
PoC
2025/04/30
CVE-2025-2558
WordPress The Wound Theme <= 0.0.1 - Local File Inclusion
wordpress
文件包含
高危
8.6
2.4%
PoC
2025/04/24
CVE-2025-2010
WordPress JobWP Plugin <= 2.3.9 - SQL Injection
jobwp
SQL注入
高危
7.5
1.8%
PoC
2025/04/19
CVE-2025-24752
Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting
essential-addons-for-elementor-lite
跨站脚本攻击
高危
7.1
1.2%
PoC
2025/04/17
CVE-2025-34028
Commvault - SSRF via /commandcenter/deployWebpackage.do
CommVault
服务端请求伪造
严重
10.0
97.6%
PoC
2025/04/15
CVE-2025-2636
RCE
InstaWP Connect < 0.1.0.86 - Local PHP File Inclusion
instawp_connect
文件包含
严重
9.8
10.4%
PoC
2025/04/11
CVE-2024-58136
KEV
RCE
Yii2 PHP Framework < 2.0.52 - Remote Code Execution
Yii
远程代码执行
严重
9.8
87.8%
PoC
2025/04/10
CVE-2025-3102
RCE
SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass
suretriggers
身份验证绕过
高危
8.1
76.2%
PoC
2025/04/10
CVE-2025-32432
CraftCMS - Remote Code Execution
Craft-CMS
远程代码执行
严重
10.0
99.8%
PoC
2025/04/08
CVE-2025-32433
RCE
Erlang/OTP SSH - Remote Code Execution
erlang-otp
远程代码执行
严重
10.0
98.8%
PoC
2025/04/08
CVE-2025-3248
Langflow AI - Unauthenticated Remote Code Execution
Langflow
远程代码执行
严重
9.8
100.0%
PoC
2025/04/04
CVE-2025-31486
Vite server.fs.deny Bypass - Local File Inclusion
Vite
文件包含
中危
5.3
40.5%
PoC
2025/04/03
CVE-2025-31489
MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads
MinIO-Console
安全配置错误
高危
8.7
2.4%
PoC
2025/04/03
CVE-2024-56325
RCE
Apache Pinot < 1.3.0 - Authentication Bypass
pinot
身份验证绕过
严重
9.8
80.2%
PoC
2025/04/01
← 上一页
113 / 543
下一页 →